Siemens Product Security Update Advisory
Overview
Siemens has released a security update addressing several vulnerabilities discovered in its SICAM 8 products.
Affected Products
- CPCI85 Central Processing/Communication: Versions prior to V26.20.
- SICORE Base System version: Earlier than V26.20.0.
Resolved Vulnerabilities
- CVE-2026-54798: Denial-of-service vulnerability in the HTTP debug interface.
- CVE-2026-54799: A signature verification vulnerability occurring during the firmware signature verification process.
- CVE-2026-54800: An unauthorized access vulnerability occurring in the default OPC UA security settings.
- CVE-2026-54801: Privilege escalation vulnerability occurring during the authentication verification process when changing the administrator account.
Response
Vulnerability Patches are available in the latest update; users must update to the latest version with the Vulnerability Patches following the instructions on the reference site.
References
- SSA-229470: Multiple Vulnerabilities in SICAM 8 Products Prior to V26.20.
- Https://cert-portal.Siemens.Com/productcert/html/ssa-229470.Html